✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3553 to 3564 of 5257
CISA Flags New Code Injection Threats in 2026: HPE OneView & Microsoft Office Under Attack
On January 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation of two critical code injection vulnerabilities: CVE-2009-0556 in Microsoft Office PowerPoint and CVE-2025-37164 affecting HPE OneView. Attackers leveraged these vulnerabilities to gain unauthorized code execution, potentially enabling lateral movement and data compromise within federal and enterprise environments. The exploitation highlighted weaknesses in outdated software and emphasized the urgency for immediate remediation to safeguard sensitive systems and data across government agencies and broader sectors. The rapid addition of these vulnerabilities to CISA's KEV Catalog reflects a broader industry trend of threat actors targeting lingering, unpatched software with advanced code injection techniques. Increasing regulatory pressure and new threat intelligence underscore the need for timely vulnerability management as attackers adapt to bypass existing defenses.
7 months ago
Kill Chain
How NoName057(16) Used DDoSia to Drive Hacktivist DDoS Attacks in 2024
In early 2024, the pro-Russian hacktivist group NoName057(16) leveraged their custom DDoS tool, DDoSia, to orchestrate large-scale distributed denial-of-service attacks targeting government, media, and institutional websites in Ukraine and Western countries. By mobilizing a network of volunteer participants through its affiliate model, NoName057(16) was able to coordinate and intensify attacks, resulting in substantial website downtime and service disruptions for organizations with links to Ukraine and the West. The campaign highlighted the effectiveness of modern hacktivist crowd-sourcing tactics and the increasing difficulty of defending against well-organized, politically motivated DDoS operations. This incident is particularly relevant in 2024 as DDoS-as-a-service tools and volunteer-driven hacktivist campaigns are on the rise, blurring the lines between state-driven threats and amateur activism. Organizations should review their DDoS mitigation and incident response defenses amid heightened geopolitical tensions and expanding threat capabilities among hacktivist collectives.
7 months ago
Kill Chain
Inside the Scattered Lapsus$ Honeypot: How Researchers Turned the Tables in 2024
In early 2024, cybersecurity researchers staged a sophisticated deception operation targeting Scattered Lapsus$, also known as ShinyHunters, by deploying a realistic but fake dataset as a honeypot. The operation was designed to lure threat actors with what appeared to be sensitive credentials and data, allowing security experts to monitor the attackers' methods and behaviors in real time. Once engaged, Scattered Lapsus$ actors attempted lateral movement and data exfiltration using various covert tools and techniques, but their actions were closely tracked and documented. This resulted in a rare glimpse into the group's tactics, techniques, and procedures, as well as validation of multiple defensive controls. This incident is particularly noteworthy as it demonstrates the growing effectiveness of proactive threat intelligence gathering through deception and honeypots. With threat groups like Lapsus$ and ShinyHunters targeting high-value data across industries, similar methods are being adopted by defenders to preemptively understand and disrupt sophisticated adversaries.
7 months ago
Kill Chain
How the 2020 Venezuelan Power Grid Cyberattack Set a New Precedent for Nation-State Warfare
In May 2020, Venezuela experienced a significant power grid disruption that coincided with an alleged US-backed military incursion. Intelligence sources and public statements, including hints from President Trump, suggested that nation-state cyber actors played a role in disabling critical infrastructure, likely by targeting unencrypted or poorly segmented network traffic in Caracas. The incident demonstrated the attackers’ use of advanced cyber capabilities to disrupt the nation's power supply, contributing to confusion and vulnerability during a period of political unrest. While the precise techniques remain classified, the attack highlighted significant weaknesses in Venezuela’s critical industrial control systems and network segmentation. The relevance of this event endures as cyber operations against power grids and critical infrastructure grow more sophisticated and frequent globally. Recent years have seen a surge in state-sponsored attacks leveraging both advanced persistent threats and rapid lateral movement, making robust east-west security, zero trust practices, and encrypted traffic defenses urgent imperatives for organizations.
7 months ago
Kill Chain
Zestix Credential Heist: 2024 Cloud Infostealer Campaign Exposes MFA Weaknesses
In early 2024, a novel threat actor known as "Zestix" orchestrated a widespread credential theft campaign targeting enterprise file-sharing environments across multiple sectors. Using advanced infostealer malware, Zestix harvested cloud credentials at scale, exploiting organizations that had not enforced multi-factor authentication (MFA). The attackers subsequently gained unauthorized access to sensitive files and regulated business data from approximately 50 companies, causing both data exfiltration and operational disruptions. The breach underlines significant weaknesses in authentication and access controls within cloud ecosystems, with impacts ranging from compromised intellectual property to potential compliance violations. The incident underscores the urgent need for robust access controls and MFA as essential defenses in today’s cloud-first environments. With identity-driven breaches rising and attackers automating large-scale infostealer campaigns, organizations face increasing regulatory and reputational pressure to modernize and enforce cloud security policies.
7 months ago
Kill Chain
Innovative Phishing Campaign Evades Detection with HTML Table-Based QR Codes
In late December 2023, a novel phishing campaign was observed in which attackers delivered emails containing QR codes crafted not from traditional images, but rendered using HTML tables. The campaign targeted end users with messages between December 22nd and December 26th, embedding visually normal but technically 'imageless' QR codes. When scanned, these QR codes redirected victims to phishing domains customized per recipient, aiming to harvest credentials. By sidestepping standard image-based security controls, these emails successfully bypassed common email security gateways designed to detect embedded malicious QR codes. This incident highlights adversary innovation in evading current email security technologies by exploiting overlooked content formats. It underscores ongoing risks as attackers adapt tactics to defeat both legacy and modern defensive controls. As sophisticated phishing methods proliferate, organizations must focus on layered defenses and continuous user education.
7 months ago
Kill Chain
State-Sponsored Cyberattack: US Targets Venezuelan Power Grid (2019)
In March 2019, a significant power outage crippled Venezuela’s capital, Caracas, and other major cities, reportedly as part of a broader campaign by the United States involving offensive cyber operations. Although official attribution remains classified, senior U.S. officials and President Trump openly hinted at the use of advanced cyberattacks to disrupt Venezuela’s electrical grid during a period of heightened political instability and efforts to capture President Nicolás Maduro. This unprecedented event marked a rare instance of publicized state-sponsored cyber warfare, raising concerns about the direct targeting of national critical infrastructure and its immediate social, political, and economic impact. This incident highlights a growing trend of nations turning to cyber operations as a tool for geopolitical leverage, targeting vital systems with the intent to destabilize adversaries. The weaponization of cyber capabilities against critical infrastructure sets a precedent for both escalation and regulatory scrutiny worldwide.
7 months ago
Kill Chain
Jaguar Land Rover Hit by Devastating 2025 Ransomware Attack: Supply Chains & Data at Risk
In September 2025, Jaguar Land Rover (JLR) suffered a devastating ransomware and extortion attack attributed to the Scattered Lapsus$ Hunters collective, a group comprising threat actors from Lapsus$, Scattered Spider, and ShinyHunters. The attackers breached JLR’s systems, forcing the automaker to halt production and send staff home. The resulting multi-week operational disruption led to a 43% drop in wholesale volumes in the third quarter, significant delays in fulfilling orders, and the confirmed theft of sensitive data. The financial toll exceeded £196 million ($220 million), prompting emergency UK government intervention to support JLR’s supply chain recovery. This incident underscores the evolving risk faced by global manufacturers from sophisticated, identity-centric ransomware actors employing both operational disruption and data theft for extortion. It highlights a broader trend of targeted attacks against critical supply chains, compounding economic impacts and regulatory scrutiny across industries.
7 months ago
Kill Chain
Generative AI Supercharges Active Directory Credential Attacks in 2026
In early 2026, organizations relying on Microsoft Active Directory experienced a significant increase in successful identity attacks fueled by generative AI technology. Threat actors leveraged AI-powered password cracking tools, such as PassGAN, capable of predicting and cracking user passwords with unprecedented speed, particularly by exploiting patterns present in common password creation habits. These attackers combined automated reconnaissance—scraping public data with large language models—to generate highly targeted guesses, accelerating credential compromise, and enabling lateral movement within corporate networks. Weak password policies, reliance on basic MFA, and the wide availability of cost-effective GPU resources contributed to the scale and efficiency of these breaches. This incident highlights the urgent need for organizations to address evolving attack methodologies, as generative AI lowers the technical barrier for credential-focused attacks and shortens breach timetables. The cybersecurity landscape is rapidly shifting towards identity-driven threats facilitated by AI, demanding stronger, adaptive protections to prevent widespread compromise.
7 months ago
Kill Chain
Ransomware at Sedgwick Government Solutions: What the 2026 TridentLocker Breach Reveals
In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network. This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.
7 months ago
Kill Chain
D-Link Legacy Router Flaw Exploited: CVE-2026-0625 Zero-Day Endangers Networks
In early January 2026, a critical security incident involving D-Link legacy DSL routers came to light as attackers actively exploited a command injection vulnerability tracked as CVE-2026-0625. The flaw, caused by improper input sanitization in the dnscfg.cgi endpoint of several out-of-support D-Link DSL gateway models, allowed unauthenticated remote attackers to execute arbitrary shell commands and potentially gain full control over affected devices. Although the exploit was first detected by Shadowserver Foundation honeypots, the method was not previously public, raising the risk of widespread attacks on consumer and small business network infrastructure. Impacted routers—including the DSL-526B, DSL-2640B, DSL-2740R, and DSL-2780B—are end-of-life and will not receive security updates, leaving users exposed unless devices are decommissioned or isolated. This incident highlights the persistent risks associated with legacy, unsupported network hardware across both consumer and SMB environments, particularly as attackers increasingly exploit unpatched, remotely accessible routers. It underscores the urgent importance of retiring end-of-life devices or segmenting critical networks, as well as the need for improved asset management strategies in the face of rising supply-chain and infrastructure vulnerabilities.
7 months ago
Kill Chain
Critical n8n Vulnerability Enables Authenticated Command Execution (CVE-2025-68668)
In January 2026, a critical vulnerability (CVE-2025-68668) was disclosed in n8n, an open-source workflow automation platform, allowing authenticated users with workflow modification privileges to execute arbitrary system commands on the host server. The flaw, caused by a sandbox bypass in the Python Code Node (Pyodide), impacted all n8n versions from 1.0.0 up to 2.0.0. Prompted by Cyera Research Labs’ findings, the n8n team released version 2.0.0 as a fix and advised urgent security configuration changes or feature disablement as interim measures. The vulnerability poses high risks for supply-chain and SaaS environments using n8n in production, potentially enabling lateral movement or privilege escalation. This incident underscores the continued threat from vulnerabilities in low-code/no-code and automation platforms, especially as attackers increasingly leverage authenticated access and workflow manipulation to escalate privileges. Organizations should review security settings of workflow platforms due to a growing pattern of exploitation in automation pipelines.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

